FSSO Authentication Issue-Same Credentials, Different IP
FSSO Authentication Issue: Same Credentials, Different IP – No Access
We’ve identified an issue with Fortinet Single Sign-On (FSSO) where users are unable to authenticate when connecting from a different IP address using the same username and password.
Problem Overview: When a user logs in from one IP address, FSSO successfully authenticates and grants access. However, if the same user attempts to connect from a different IP (e.g., switching networks or subnet), authentication fails—even though the credentials remain unchanged.
Possible Cause: FSSO relies on IP-to-user mapping via polling agents or DC agents. If the IP address changes and the new IP isn’t mapped to the user in the collector agent’s cache, the firewall cannot verify the user identity, resulting in failed authentication.
Suggested Additional Steps:
1) Force logoff from AD to trigger a fresh login event.
2) Restart the FSSO Collector Agent service to refresh mappings.
3) Ensure all domain controllers are properly polled by the collector agent.
Work Around:
Option 1:
Manually clear the user’s session entry from the FSSO Collector Agent or polling source (e.g., DC Agent), and remove any stale AD session records. This will trigger a fresh authentication and update the IP-user mapping.
Option 2:
Flush the DNS cache on the user’s device and perform a Windows logout/login or reconnecting to the network. This process helps clear any stale network records from the system and initiates a fresh authentication cycle, which can assist in resolving FSSO-related login issues.
